summaryrefslogtreecommitdiffstats
path: root/block
diff options
context:
space:
mode:
authorBart Van Assche <bart.vanassche@sandisk.com>2017-05-04 00:31:29 -0700
committerJens Axboe <axboe@fb.com>2017-05-04 08:23:39 -0600
commit18d4d7d0571f5acc9de638ea3a33e8064deaceca (patch)
tree928660479764e5f64aa60ea5492dde310de268d7 /block
parentf57de23ac9019ea84c548a1637d5562ef07a8f7e (diff)
downloadlinux-0-day-18d4d7d0571f5acc9de638ea3a33e8064deaceca.tar.gz
linux-0-day-18d4d7d0571f5acc9de638ea3a33e8064deaceca.tar.xz
blk-mq: Do not invoke queue operations on a dead queue
In commit e869b5462f83 ("blk-mq: Unregister debugfs attributes earlier"), we shuffled the debugfs cleanup around so that the "state" attribute was removed before we freed the blk-mq data structures. However, later changes are going to undo that, so we need to explicitly disallow running a dead queue. [Omar: rebased and updated commit message] Signed-off-by: Omar Sandoval <osandov@fb.com> Signed-off-by: Bart Van Assche <bart.vanassche@sandisk.com> Reviewed-by: Hannes Reinecke <hare@suse.com> Signed-off-by: Jens Axboe <axboe@fb.com>
Diffstat (limited to 'block')
-rw-r--r--block/blk-mq-debugfs.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/block/blk-mq-debugfs.c b/block/blk-mq-debugfs.c
index 1579af6fcbedc..347fbb8e059cf 100644
--- a/block/blk-mq-debugfs.c
+++ b/block/blk-mq-debugfs.c
@@ -102,6 +102,14 @@ static ssize_t queue_state_write(void *data, const char __user *buf,
struct request_queue *q = data;
char opbuf[16] = { }, *op;
+ /*
+ * The "state" attribute is removed after blk_cleanup_queue() has called
+ * blk_mq_free_queue(). Return if QUEUE_FLAG_DEAD has been set to avoid
+ * triggering a use-after-free.
+ */
+ if (blk_queue_dead(q))
+ return -ENOENT;
+
if (count >= sizeof(opbuf)) {
pr_err("%s: operation too long\n", __func__);
goto inval;